Skip to content
Docs

资产生成 API Keys

Use API keys to authenticate 资产生成 requests. You can:

  • Create a key in the dashboard, with the Vercel CLI, or via the Vercel API
  • View your keys and their usage
  • Attribute a key's spend to your team or an individual member
  • Delete or revoke a key

You can optionally give any key a budget to cap how much it can spend (see Budgets), and choose whether its spend is attributed to your team or to a member (see Spend attribution). For how to use a key in your code, see Authentication.

When a team member leaves your team, Vercel deactivates any API keys they created. If you need authentication that isn't tied to a specific person, use OIDC tokens on Vercel deployments.

Create a key from the dashboard, the Vercel CLI, or the Vercel API.

  1. Open the API Keys page. Go to the 资产生成 API Keys page and click Create key.
  2. Name and create the key. Give the key a name and create it.
  3. Save the key. Copy the key value immediately (you cannot retrieve it again) and save it as AI_GATEWAY_API_KEY.

Make sure you're on the latest CLI version. The key is created under your current CLI scope; check it with vercel whoami, change it with vercel switch, or pass --scope <team> per command.

terminal
vercel ai-gateway api-keys create --name my-api-key

Copy the key value immediately. You cannot retrieve it again.

Call POST /v1/api-keys with a Vercel access token, passing the team ID as a query parameter.

terminal
curl -X POST "https://api.vercel.com/v1/api-keys?teamId=$VERCEL_TEAM_ID" \
  -H "Authorization: Bearer $VERCEL_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{ "purpose": "ai-gateway", "name": "my-api-key" }'
FieldTypeDescription
purposestringRequired. Use ai-gateway.
namestringOptional. Human-readable name.
projectIdstringOptional. Scope the key to a Vercel project.
expiresAtnumberOptional. Expiry as a UNIX timestamp (ms).

The response includes apiKeyString (the secret; save it now) and the key's id.

To cap how much a key can spend, add a budget when you create it. See Budgets. By default, a new key's spend is attributed to you. To attribute it to your team instead, see Spend attribution.

Every 资产生成 API key is attributed to either your team or a single team member. Attribution controls whose budget the key's spend counts against:

  • User: the key's spend counts toward both the team budget and the key creator's user budget.
  • Team: the key's spend counts toward the team budget only.

Budgets stack rather than split. A key attributed to a member counts against both that member's budget and the team budget on every request, and the request is rejected if either is exceeded. The team budget caps total spend, and a user budget caps one member's share of it.

New keys default to User attribution. A key with no attribution set counts toward the Team, which covers keys created before spend attribution shipped and any key created through the API without metadata.spendAttribution. Only team Owners and 资产生成 Budget Managers can set or change a key's attribution.

  1. Open the create- or edit-key dialog. On the 资产生成 API Keys page, click Create key, or open a key's ··· menu and select Edit key.
  2. Set spend attribution. Under Spend attribution, choose User or Team.
  3. Save.

Set metadata.spendAttribution when you create a key:

terminal
curl -X POST "https://api.vercel.com/v1/api-keys?teamId=$VERCEL_TEAM_ID" \
  -H "Authorization: Bearer $VERCEL_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
    "purpose": "ai-gateway",
    "name": "my-api-key",
    "metadata": { "spendAttribution": "user" }
  }'
FieldTypeDescription
metadata.spendAttributionstringuser (default) or team. Only team Owners and Budget Managers can set this field.

To change the attribution of an existing key, use the dashboard.

List your keys from the dashboard, the Vercel CLI, or the Vercel API.

The 资产生成 API Keys page lists every key with its last-used time. A budgeted key also shows its spend against the limit; see Budgets.

List all 资产生成 keys (the CLI injects your current team scope if you omit teamId):

terminal
vercel api "/v1/api-keys?purpose=ai-gateway"
terminal
curl "https://api.vercel.com/v1/api-keys?teamId=$VERCEL_TEAM_ID&purpose=ai-gateway" \
  -H "Authorization: Bearer $VERCEL_TOKEN"

A key's editable properties are its budget and its spend attribution. To add, change, or remove a budget, see Budgets. To change attribution, see Spend attribution. To change anything else, such as the name, delete the key and create a new one.

Deleting a key immediately invalidates it. Any request using it afterward fails authentication.

On the API Keys page, open a key's ··· menu to delete it, or use the ··· menu next to Create key to delete all keys at once.

List your keys to find the id of the one to revoke:

terminal
vercel api "/v1/api-keys?purpose=ai-gateway"

Each key in the response has an id. Pass it to the delete endpoint:

terminal
vercel api "/v1/api-keys/$API_KEY_ID" -X DELETE

The CLI asks for confirmation before deleting. To revoke several keys, repeat the delete for each id.

List keys with GET /v1/api-keys (see View a key) to get each id, then delete one:

terminal
curl -X DELETE "https://api.vercel.com/v1/api-keys/$API_KEY_ID?teamId=$VERCEL_TEAM_ID" \
  -H "Authorization: Bearer $VERCEL_TOKEN"

If a raw key has leaked, revoke it without authentication by reporting it:

terminal
curl -X POST "https://api.vercel.com/external/compromised_secret" \
  -H "Content-Type: application/json" \
  -d '{ "secret": { "api_key": "vck_..." } }'
Last updated September 8, 2026

Was this helpful?

supported.